pub struct SigningKey { /* private fields */ }Expand description
Backing type for the signature.signing-key resource.
sign is one-shot and stateless per call, so the key carries no
per-operation state. extractable gates %export only.
Implementations§
Source§impl SigningKey
impl SigningKey
Sourcepub fn from_material(
view: &mut WasiWebcryptoCtxView<'_>,
material: SigningKeyMaterial,
) -> Result<Resource<SigningKey>, Error>
pub fn from_material( view: &mut WasiWebcryptoCtxView<'_>, material: SigningKeyMaterial, ) -> Result<Resource<SigningKey>, Error>
Place embedder-supplied signing key material in the store’s table as
a signature.signing-key handle.
The returned handle is indistinguishable from one a guest minted: it
lives in the same table under the same retention accounting (charged
here, released when the resource leaves the table), and the
existing getters (can-sign, extractable, the algorithm-*
family) answer from material’s algorithm binding and policy. It is
what an embedder’s own host-implemented import returns to the guest
when its bindgen! maps the polymorph:webcrypto/signature resources
onto these types via with.
material already carries its algorithm binding and policy from its
core constructor (for example
SigningKeyMaterial::import_ed25519_seed), so admission — key
validation, the at-least-one-usage mint rule — happened there.
An embedder wanting the pair calls SigningKeyMaterial::public
before moving material here, then wraps the derived public half
with VerifyingKey::from_material — the doctest below does both.
§Errors
Fails when the store’s retention budget cannot admit the resource (the same recoverable condition a guest mint reports), or when the resource table cannot accept the push.
§Examples
use wasmtime::component::ResourceTable;
use polymorph_webcrypto_wasmtime::{
SigningKey, SigningKeyMaterial, SigningPolicy, VerifyingKey, WasiWebcryptoCtx,
WasiWebcryptoCtxView,
};
let mut ctx = WasiWebcryptoCtx::new();
let mut table = ResourceTable::new();
let mut view = WasiWebcryptoCtxView {
ctx: &mut ctx,
table: &mut table,
};
// An obviously synthetic seed, not real key material.
let seed = [7u8; 32];
let policy = SigningPolicy {
sign: true,
extractable: false,
};
let material = SigningKeyMaterial::import_ed25519_seed(&seed, policy)?;
let public = material.public();
let signing_key = SigningKey::from_material(&mut view, material)?;
let verifying_key = VerifyingKey::from_material(&mut view, public)?;Trait Implementations§
Auto Trait Implementations§
impl Freeze for SigningKey
impl RefUnwindSafe for SigningKey
impl Send for SigningKey
impl Sync for SigningKey
impl Unpin for SigningKey
impl UnsafeUnpin for SigningKey
impl UnwindSafe for SigningKey
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more